CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18201

mediumCVSS 5.5covered by 2 sourcesfirst seen 2026-07-29
A remote, authenticated attacker can exploit multiple vulnerabilities in Keycloak to bypass security measures and manipulate data.

CSIRTS triage

What
Keycloak has multiple vulnerabilities that allow remote authenticated attackers to bypass security measures and manipulate data.
Who is affected
Authenticated users of Keycloak are affected.
Urgency
Remediation is medium urgency as the vulnerabilities are unpatched and could be exploited.
Action
Monitor for updates and apply patches when available.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-18201

Get an email if CVE-2026-18201 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-18201

CVE.org record

Embed the live status

CVE-2026-18201 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18201 status](https://www.csirts.com/badge/CVE-2026-18201)](https://www.csirts.com/cve/CVE-2026-18201)